THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-pf96-p4fj-6566 (medium) — HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated

[GHSA] GHSA-pf96-p4fj-6566 (medium) — HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated

medgithub_advisoriesPublished 2026-09-08

GHSA-pf96-p4fj-6566 Severity: medium CVE: CVE-2026-84380

HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated

### Summary

HTTPX2 can automatically add a `Content-Length` header to a request that already contains a caller-supplied `Transfer-Encoding` header. The resulting HTTP/1.1 request contains both framing headers, which can create an ambiguous message bound

Indicators of compromise

Original source: https://github.com/advisories/GHSA-pf96-p4fj-6566